Jump to content

playing with Charles ssl proxy


Recommended Posts

Hi all

I have spent the weekend setting up a Charles proxy to intercept and decode SSL traffic on my computer

see image of my login interception. on yes it did intercept the correct login detail while encrypted


I can see some potential with a pineapple, captive portal . the rubberduck, and charles

for charles to work, it must have its own certificate in the trusted store, hence captive portal and rubber duck as mean of placing the certificate.

I will play with this some more over the next few weekends,

experiments ongoing..

Link to comment
Share on other sites

Hi Cooper

Yes, the duck would be help install the certificate, put it on github or some other file hosting site and call down by the tinyurl web site, then using the CMD and MMC, i need to work out the key strokes to do it, need to sit down and play with it.

the captive portal would do the same as well, install the certificate into both truststores.

will keep posting as I work things out.

Link to comment
Share on other sites

I have played with charles some more this weekend, After I flashed my Pineapple with the latest firmware, I turned it on while loading some infusions.

It captured all SLL traffic while installing the infusion, see photo of the capture.


it passed the pinapple traffic.

but when I connected another laptop to the pineapple and browsed the internet, i could browse, but the fraffic wasn't captured.

Still more playing needed, I will need to configure the connecting computer to connect to the proxy's IP and port

Edited by Swamppifi
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...